What we do
01  Advanced Infrastructure 02  Applied AI & Data 03  AI Cybersecurity 04  AI Assurance
Engagements
AI estate inventory Assurance review
Industries
Financial Services Government & Public Sector Energy & Utilities Telecommunications Healthcare & Life Sciences Transport & Logistics Industrial & Manufacturing Retail, Hospitality & Real Estate
Research
The Trust Maturity Model The GCC Assurance Index Readiness self-assessment Case studies Perspectives Sector briefings Technology evaluations
Company
About us Partners Events Careers Contact العربية Talk to our team
Research  ·  Government & public sector

Your supplier never read the contract.

What we are watching in this sector, and the research that touches it. This is the research view; the services view is on the industry page.

SECTOR VIEWUPDATED 26 AUGUST 2026RESEARCH ONLY
What we are watching

Three questions we put to every estate in this sector.

01

Supplier obligations after onboarding

Whether supplier obligations were re-scoped after onboarding, or only at it.

02

Residency evidenced per system

Whether residency is evidenced per system or asserted per programme.

03

An evidence pack that predates the request

Whether the evidence pack exists before the request rather than after it.

Obligations in force

What is already due, and what is coming.

Every obligation below is dated, named and externally imposed. Read them against what your organisation could evidence this week rather than against what it intends to build.

DURING 2026UAE Cyber Security Council

Mandatory PQC migration-plan submission by government entities

An automated cryptographic inventory and a formally approved transition plan.

UAE
ROLLING OUT 2026UAE — NCAP

National Cyber Accreditation Programme restricts which providers may serve critical infrastructure

That your security and cloud suppliers hold the required accreditation.

UAE
IN FORCEDESC (Dubai)

Information Security Regulation v3 — 13 security domains

Annual penetration testing, quarterly vulnerability assessment; non-compliance means removal from procurement lists.

UAE
IN FORCEUAE federal — NESA

Information Assurance Standard v2 — 188 controls, 39 mandatory Priority One

Demonstrated P1 coverage across IAM, patching, data protection and incident response.

UAE
IN FORCEUAE

Secure Supply Chain Programme

Software Bill of Materials transparency for government procurement.

UAE
2024UAE — AIATC

Law No. 3 of 2024 establishing the Abu Dhabi AI and Advanced Technology Council

Programme-level AI governance aligned to emirate policy.

UAE
JUN 2024UAE

Charter for the Development and Use of AI — 12 principles

Documented alignment for AI deployed in public service.

UAE
IN FORCEKSA — NCA

ECC-2:2024 — 4 domains, 28 subdomains, ~110 controls

Cybersecurity roles filled by qualified Saudi nationals; data localisation via NDMO.

KSA
IN FORCEQatar — NCSA

National Information Assurance policy

Sector-specific AI mandates for financial institutions.

QATAR

Reproduced from the Orvix Government & public sector industry page. Last reviewed 26 August 2026.

Looking for services rather than research?

The industry page sets out what we actually do in this sector and who delivers it.

Government & public sector →